Back to home

Legal

Data Processing Addendum

Effective date: August 29, 2026

When you record information about your customers in QuoCAD, you decide what is collected and why — you are the controller, and we process it for you. This document is the written processor agreement for that arrangement. It applies automatically when you accept the Terms of Service, so there is nothing to sign or request.

1. What this document is, and when it applies

This Data Processing Addendum (“DPA”) forms part of the QuoCAD Terms of Service. It applies whenever we process personal data about your customers, your contacts, or other people on your behalf while providing QuoCAD to you. You do not need to sign or request it: you accepted this DPA when you accepted the Terms of Service, and we retain a record of that acceptance — who accepted, which version, and when.

It does not apply to your own account information — your name, email, workspace and billing details. We decide how that is used, so we are the controller for it and the Privacy Policy governs it.

Where this DPA and the Terms of Service disagree about the processing of your customers' personal data, this DPA governs. Everything else in the Terms, including the limitation of liability in section 21 of the Terms, continues to apply.

In this document, “controller”, “processor”, “personal data”, “processing”, “data subject” and “personal data breach” carry the meaning given to them in the applicable data protection law — the UK and EU GDPR, and comparable Canadian, US state and other privacy laws where they apply to you.

2. Your role and ours

You are the controller of the personal data you enter into QuoCAD about other people. You decide what to collect, why, and how long to keep it. QuoCAD is your processor: we hold and process that data to provide the service to you.

You represent and warrant, on a continuing basis, that: you have and will maintain a lawful basis under applicable law for every category of personal data you enter into QuoCAD or instruct us to transmit; you have given every person concerned the notice, and where required obtained the consent, that applicable law requires — including notice that a processor operating from Canada and using United States infrastructure will hold their data; your instructions to us, including how you configure and use the product, comply with applicable data protection law; the personal data you enter is accurate, and you will correct or delete it when it stops being accurate; and where you are yourself a processor for someone else — for example a property manager whose own client owns the data — you hold that party's authority to appoint us as a subprocessor on the terms in this DPA.

Each of those is a material term of this DPA. If you breach one, we may, on notice, suspend or restrict the affected processing; and you instruct us by this DPA, as a documented instruction under section 4, to delete the affected data if you have not done so within a reasonable period after we ask. We do not check whether you have complied, and nothing in this DPA obliges us to.

None of that reduces what we owe you. Sections 4 to 12 bind us whatever you did or did not do — a warranty from you is an allocation between us, not a transfer of our obligations as processor.

2a. Your indemnity

Section 17 of the Terms of Service (Your indemnity) applies in full to the matters in this DPA. For the avoidance of doubt it covers, without limiting section 17:

The defence procedure, the carve-outs and the exclusion from the liability cap in section 17 of the Terms apply to this indemnity. Two additions specific to data protection: it does not cover a fine imposed on us for our own failure to meet an obligation applicable law places on us as a processor, and it is in addition to, and does not replace, the right of recourse between controller and processor under Article 82(5) of the GDPR.

This indemnity is not subject to the liability cap in section 13 or in the Terms of Service, is not subject to the exclusion of indirect loss in section 13, and survives termination of this DPA and of your subscription.

  • Your breach of any warranty in section 2, or of the covenant in section 3 about data you will not enter.
  • The absence of a lawful basis, notice or consent for personal data you enter into QuoCAD or instruct us to transmit.
  • An instruction from you that infringes applicable data protection law.
  • Your failure to notify a person or a supervisory authority where the law required you to.
  • Files, imagery and content you upload.
  • Documents and messages you send through QuoCAD or links you share from it, including any claim about consent to receive them.

3. What we process, and for how long

Subject matter and duration: the provision of QuoCAD to you, for as long as your workspace exists. Processing ends when the data is deleted under section 10.

Nature and purpose: hosting, storing, transmitting and displaying the records you create; producing quotes, invoices, reports and exports from them; sending the documents and notifications you choose to send; and the support, security, backup and troubleshooting work needed to keep the service running.

Types of personal data: names, email addresses, phone numbers, business and property addresses, job site locations, notes you write about a person or property, quote and invoice contents including amounts, payment status and payment references, message and delivery records for documents you send, and any personal data contained in files or imagery you upload.

Categories of data subjects: your customers and prospective customers; the individual contacts at those organizations; the recipients of quotes, invoices and other documents you send; and the members of your own workspace.

Special category data is not required by QuoCAD and the product has no feature that asks for it.

You will not enter, upload, or instruct us to process: special category data within the meaning of Article 9 of the GDPR — health, biometric, genetic, racial or ethnic, political, religious, trade union, sex life or sexual orientation data; criminal offence data within the meaning of Article 10; government-issued identifiers such as social insurance, social security, driver's licence or passport numbers; payment card numbers or financial account numbers; protected health information; or personal data about anyone under 18. That applies to free-text fields — job notes, contact notes, scope and approval text — just as much as to structured ones, and free text is where it actually happens.

QuoCAD is not designed, configured or offered for that data. We make no representation that our measures are appropriate for it, and as between you and us we accept no liability arising from your entering it. If we become aware of such data in your workspace we may require you to delete it, and if you do not do so within a reasonable period after we ask, you instruct us by this DPA to delete it, and we are not liable for that deletion.

4. We process only on your instructions

We process your customers' personal data only on your documented instructions, including for international transfers, unless a law we are subject to requires otherwise. If that happens we will tell you before processing, unless that law forbids telling you.

Your instructions are: this DPA, the Terms of Service, your configuration of the product, your use of its features, and any further written instruction you give us. A further instruction binds us if an owner or admin of your workspace gives it in writing to the address in section 15 and it is within the scope of the service we provide to you; we may act on an instruction that appears to come from an authorised person. An instruction that needs work outside the ordinary operation of the product is subject to section 8.

We do not use your customers' personal data for our own purposes, other than to generate the Service Data described in section 4a. We do not sell it, do not share it with advertisers or data brokers, do not use it for advertising, and do not use it to train machine-learning models.

If we consider an instruction to breach applicable data protection law, we will tell you.

4a. Service Data, and what we hold in our own right

Running QuoCAD generates records of its own — who signed in, what an administrator did, which request failed, how much of a metered feature a workspace used, that a subscription was billed. Those records are about the operation of the service rather than about your customers, and we hold them in our own right, as controller, for our own purposes. This DPA calls them Service Data. The Privacy Policy governs them, and your instructions under section 4 do not reach them.

Service Data is: the account and workspace records of the person who holds the account with us — the account owner's and administrators' names, email addresses and roles; billing and subscription records, including plan, invoices and payment references; the record of your acceptance of the Terms of Service, this DPA and the Privacy Policy, described in section 9 of the Privacy Policy; security and audit records — sign-in, permission changes, exports, administrative actions, and the support-access grants described in section 5; diagnostic and error reports; request logs and rate-limiting counters; the delivery, bounce and complaint signals our email provider returns to us, in which the recipient is identified by a one-way hash rather than by an address; webhook payloads from payment processors; usage counts for metered features; and product analytics keyed to a user and workspace identifier rather than to the contents of your records.

We hold Service Data to operate, secure, bill, support, troubleshoot and improve QuoCAD, to meet our own legal, tax and accounting obligations, and to establish, exercise and defend legal claims. Those are our purposes, decided by us. You are not the controller of Service Data, and an instruction under section 4 or an election under section 10 does not reach it. Where an individual has a right in Service Data under the law that applies to them, we answer that request ourselves, as controller.

The boundary matters, so here it is exactly. Service Data is produced by our operation of the service. It is not a copy of your records, and we do not extract your customers' records into a separate store for our own use. The record of who you sent a document to, when it was sent, and whether it was opened is part of your workspace content — you can see it in the product, and we hold it as your processor. That record is append-only, so it cannot be edited or deleted, and the self-service export does not currently include it; ask us and we will produce it, as section 10 describes. What we hold in our own right is the operational layer beneath it: the provider's delivery signals, our request and rate-limiting logs, and our own counts.

You instruct us, as a documented instruction under section 4, to produce aggregated and statistical information from Service Data and from your workspace, and to use it to operate, secure, support, improve and plan the capacity and cost of QuoCAD. The output of that work contains no personal data: it is produced in a form from which neither you, your workspace, your customers, nor any individual can be identified, whether on its own or together with information we or a recipient are reasonably likely to hold. Once it is in that form it is outside this DPA and we may use it without restriction. We will not attempt to re-identify anyone from it, will not build or modify a profile about any individual, and will not use your customers' personal data to train machine-learning models. Section 15 of the Terms of Service records the same instruction.

We do not combine your customers' personal data with personal data we hold for another customer, or with personal data we collect from our own dealings with an individual, other than to detect and respond to security incidents, to resist malicious, deceptive, fraudulent or illegal activity, to debug and repair errors, and for internal use to build or improve the quality of our services — which never includes building or modifying a profile about an individual.

Service Data is retained as section 9 of the Privacy Policy describes, and some of it deliberately outlives your workspace: the acceptance records, the records we must keep for tax, accounting or legal reasons, and the security and audit records, whose whole purpose is to answer questions about the past. Deleting your workspace under section 10 deletes your customers' personal data. It does not delete those, and section 10 says so.

None of this reduces what we owe you as processor. Where a Service Data record happens to contain personal data about one of your customers — a name inside an error report, an email address inside a webhook payload from a payment processor — that personal data stays inside this DPA: sections 4, 5, 6, 8, 9, 10 and 12 continue to apply to it so far as the record allows us to act on it, and we hold it under the same confidentiality, security, breach-notification and transfer terms as everything else. Where such a record is one we must keep for a legal, tax, security or audit reason, section 10's exceptions apply to it, and we will tell you which exception we are relying on if you ask.

5. Confidentiality and access

Everyone we allow to process your customers' personal data is bound by a duty of confidentiality and is only given the access their role requires.

Support access to a workspace requires a grant that records the reason and the scope, that expires, and that can be revoked. Grants and administrative actions are written to an audit trail that application users cannot alter.

To be exact about the scope of that control, because you may need to describe it in your own records: the grant, its scope, its expiry and its revocation govern and record the authorisation to access a workspace, and are written to the audit trail. It is not at present a technical control that independently prevents access by a platform administrator holding no grant. We are implementing that enforcement and will update this section when it is in place.

6. Security measures

We take the technical and organizational measures required by Article 32 of the GDPR and equivalent laws. Stated as specific measures rather than assurances, because you may need to describe them in your own records:

Workspace isolation is enforced by the database itself. We require row-level security on tables holding workspace data, keyed to an active membership, so one workspace cannot read another's rows even if application code were wrong. An automated cross-tenant isolation suite runs against a database rebuilt from scratch whenever we change the database, and a cross-tenant leak fails the build.

Data is encrypted in transit (HTTPS, with HSTS) and at rest by our database and storage provider.

Payment card numbers never reach our systems. Card entry is hosted by the payment processor; we store a payment reference, an amount and a receipt link.

Share links for quotes and invoices are stored as one-way hashes and expire. The link itself is never stored; a link stops working when the document it points to is voided, revised or refunded, it can no longer take a payment once the invoice is paid, and it can be revoked on demand from the document itself.

Requests are rate-limited, payment and email webhooks are signature-verified before processing, and the application sets a strict content security policy.

Production access is limited to the owner and named platform administrators, and administrative actions taken inside QuoCAD are written to an audit trail.

Three things we do NOT currently provide, stated plainly because a processor contract that omits them would mislead you: multi-factor authentication for user sign-in, customer-managed encryption keys, and any formal security certification such as SOC 2 or ISO 27001. If your compliance programme requires one of these, tell us before you rely on QuoCAD for that data.

You have read this section, including the three measures we say we do not provide, and you confirm that the measures described are appropriate to the risk presented by the personal data you choose to enter into QuoCAD, taking Article 32(1) into account. Deciding whether QuoCAD is suitable for a given category of data is yours. So is the strength and confidentiality of your credentials, the security of the devices your workspace members use, and limiting which members can see customer, property and job information. You are responsible, as between you and us, for anything done through valid credentials of your workspace; that allocation does not change what an event is, and if unauthorised access to personal data occurs on our systems we will treat it as a personal data breach and notify you under section 9 whether or not valid credentials were used. That acknowledgement is an allocation between you and us. It does not reduce our own obligation under Article 32 to take measures appropriate to the risk of the processing we actually carry out, which continues to apply whatever you acknowledge.

We may change these measures over time, but will not reduce the overall level of security while this DPA is in force.

7. Subprocessors

You give us general written authorization to engage subprocessors. The current list, what each one receives and where it processes data, is maintained on our Subprocessors page — it is part of this DPA by reference. Section 7a explains which providers on that page are not our subprocessors.

Before a new subprocessor starts processing your customers' personal data, we will update the Subprocessors page and email your workspace's owner and admin addresses at least 30 days beforehand. You do not need to ask for that notice.

You may object within 30 days of that notice, in writing from an owner or admin of your workspace, stating specific and documented data protection grounds — a commercial preference is not a ground. Where you object within that period we will not engage that subprocessor for your workspace's data before the 30 days expire or your objection is resolved, whichever is earlier. We may propose a commercially reasonable alternative, but we are not obliged to; if we do not, you may terminate the part of the service that depends on that subprocessor and receive a pro-rata refund of prepaid fees for the unused period. That termination and refund is your sole and exclusive remedy for an objection.

Where we have to replace a subprocessor urgently to keep the service secure or running — a provider suffers an incident, loses a certification, or stops serving us — we may do so, and we will update the Subprocessors page and tell you as soon as we reasonably can afterwards. Where you object to a replacement engaged this way, the objection and remedy above apply from the date we tell you.

We impose data protection obligations on each subprocessor no less protective than those in this DPA, and we remain responsible to you for their performance.

7a. Providers that are not our subprocessors

A subprocessor is a provider that processes your customers' personal data on our instructions, to help us provide QuoCAD to you. Section 7 governs those — the list, the 30 days' notice, the objection right, and our responsibility for their performance. Two of the providers on our Subprocessors page are not that: the payment processors decide for themselves what to do with the cardholder data they receive and carry their own legal duties directly to the person concerned, so for that activity they are independent controllers rather than our subprocessors and section 7 does not apply to it. The map providers are our subprocessors, and section 7 applies to them in full; they are also independent controllers for the direct connection your browser makes to them, which this section explains because the two roles are easy to confuse.

Card payments. If you accept payments, your customer pays you on your own connected Stripe account, or your own Square account where you use Square. You are the merchant of record, as section 10 of the Terms of Service sets out, and we take no fee from those payments and never hold the funds. The card details are entered on the processor's own pages and never reach our systems — section 6 says so, and what we store is a payment reference, an amount and a receipt link. The processor handles the cardholder's data as an independent controller, under its own agreement with you, its own card-network rules, and its own obligations under financial-crime, sanctions and tax law. We cannot instruct it about that data, cannot stop it processing it, and do not answer for it. Your agreement with that processor governs it.

Stripe is also our subprocessor for two narrower things: the billing details we send it for your own subscription — your billing name, email and address — and the recipient address and invoice amount we pass when we create a payment page for one of your invoices. The first of those is your account information, for which section 1 makes us the controller rather than your processor, so it sits outside the personal data this DPA covers; the second is your customers' personal data and section 7 applies to it. Square receives nothing for your own subscription: QuoCAD's own billing runs on Stripe alone.

Maps. Mapbox and Azure Maps supply the map and satellite imagery QuoCAD draws on, and Mapbox also geocodes the addresses you search for. Imagery is streamed to the browser that is displaying it, which fetches it from the provider directly — so the provider sees that browser's IP address and user agent, and the map area being requested. That includes the browser of a customer who opens a quote you sent: a site plan on that page loads Mapbox imagery directly. When you ask for an automatic travel estimate, your base address and the job address are sent from our servers to Mapbox. Neither provider receives your customer's name, contact details, notes, or the contents of a job, quote or invoice. We instruct both providers on your behalf and they are our subprocessors for that; each also decides for itself, as an independent controller, what to do with the request its own systems receive from a browser, under its own terms. Section 12 of the Terms of Service sets out your own obligations to those providers.

What this section changes about the objection right, and what it does not. The objection right in section 7 does not apply to a payment processor you connect yourself, for the practical reason that we cannot substitute an account you opened under your own agreement with that provider. It does apply to the map providers. If you object to one on specific and documented data protection grounds, section 7's remedy applies as written — you may terminate the part of the service that depends on that subprocessor and receive a pro-rata refund of prepaid fees for the unused period — and you should know before you rely on it that QuoCAD cannot operate without a map provider, so in practice the part that depends on one is the whole of it. You can trace from imagery your organization owns or licenses instead of live imagery for a given job, which section 12 of the Terms of Service already contemplates, but that does not stop a provider serving the base map. Whatever role a provider is in, we still send it the least the feature needs, and it stays named on the Subprocessors page.

Everything on the Subprocessors page is our subprocessor and section 7 applies to it in full, except the payment processors' handling of cardholder data, which the second paragraph of this section describes.

8. Helping you answer your customers

If one of your customers asks to see, correct, delete, restrict, object to, or receive a portable copy of their information, that request belongs to you. We have no way to verify who they are, and it is your record — so they should contact you, not us.

The product is built so you can answer most of these yourself: you can find, edit, export and delete contacts, jobs, quotes and invoices at any time, and Settings → Backup & data produces a workspace export.

Where you cannot resolve a request with the product's own tools, contact us and we will help you locate, extract, correct or remove the data. We provide that assistance at no charge for up to five requests in any twelve-month period. Beyond that, or where a request needs engineering work, a custom extraction, or more than four hours of our time, we will tell you before we start and charge our then-current professional-services rate, which we will publish or provide on request. We will not withhold assistance that applicable data protection law requires us to give because a fee is unpaid or disputed: we will do the work within the time the law allows and invoice it afterwards.

Assistance requests must come from an owner or admin of your workspace, sent to the address in section 15, and our response time runs from the point we have everything we need to act. None of this applies to a personal data breach: section 9 is never conditional on payment, on a volume, or on a threshold.

If a request reaches us directly, we will not answer it. We will tell the person to contact you and, where we can identify the workspace, tell you it happened.

9. Breach notification, and help with assessments

If we become aware of a personal data breach affecting your customers' personal data, we will notify you without undue delay. We aim to do that within 72 hours of becoming aware, and we will tell you what we know at the time rather than waiting until the picture is complete.

We become aware of a personal data breach when our security personnel have a reasonable degree of certainty that a security incident has occurred that led to your customers' personal data being compromised. We may take a short period to establish that, and we will not delay beyond what is needed to reach that certainty. Unsuccessful attempts that do not compromise the security of the data — port scans, pings, failed sign-ins, denial-of-service attempts we absorb — are not personal data breaches, and we will not report them individually.

The notification will describe what happened, the categories and approximate number of records and data subjects affected so far as known, the likely consequences, the measures taken or proposed, and a contact point. Where we cannot provide all of it at once, we will provide it in phases without further undue delay.

Notifying you, investigating, and any remediation we carry out are not an acknowledgement of fault or of liability on our part.

It is your responsibility to notify your supervisory authority and the people affected, where the law requires it. We will give you the information you reasonably need to do so.

You will tell us without undue delay if credentials, accounts or devices used to reach your workspace are compromised, or if you become aware of a breach affecting your customers' personal data that originated on your side.

We will also give you reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, to the extent these relate to our processing and the information is not otherwise available to you — in practice, by giving you information about how we process. Completing your assessment, and every conclusion in it, is yours. Where assistance goes beyond providing information we already hold, section 8's rate applies.

10. Deletion and return

You can export your workspace at any time from Settings → Backup & data, and you can delete individual records in the product at any time. The self-service export covers your jobs, contacts, quotes and workspace settings. It does not currently include invoices, payment records, job media or site photos — ask us and we will produce those.

When your workspace is deleted, the personal data in it is deleted. Deleted items are retained for at least 30 days before their underlying files are purged, so that an accidental deletion can be reversed if you ask us within that period. There is no self-service undelete, purging happens as part of scheduled and operator-run maintenance rather than at a fixed moment, and we do not guarantee that any particular item can be recovered. Export downloads expire after 24 hours and the generated file is removed after that.

At the end of the provision of services you choose whether we delete your customers' personal data or return it. Tell us in writing which you want within 30 days of termination. We satisfy a return by making all of your customers' personal data available to you for download — the self-service export, together with the invoices, payment records, job media and site photos it does not currently cover, which we will produce at no charge on request. We are not obliged to produce it in another format, schema or medium, and section 8's rate applies to a return in a non-standard format or to assistance beyond producing that data. If you tell us nothing within those 30 days, we delete. We have no obligation to keep your data after that window, and we are not responsible for data you did not export within it.

We are not responsible for data that you, or a member of your workspace, deleted.

Two exceptions, which apply to every provider and are stated here so they do not surprise you. Records we must keep for tax, accounting or legal reasons — invoices and payment records — are retained for the period the law requires. Security and audit records, and the record of your acceptance of these documents described in section 9 of the Privacy Policy, are retained beyond ordinary content because their purpose is to answer questions about the past. All of them remain protected by this DPA for as long as we hold them.

Backups are deleted on their own rotation rather than individually edited. Data in a backup is not restored to live systems except to recover from a failure.

11. Demonstrating compliance

We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits conducted by you or an auditor you appoint.

In practice: ask us and we will answer a security questionnaire and provide the documentation we hold. We do not currently hold a SOC 2 or ISO 27001 report to send instead — see section 6.

An on-site or hands-on audit may be requested no more than once in any twelve months, unless a supervisory authority requires otherwise or we have notified you of a breach. It must be scheduled reasonably in advance, must not unreasonably disrupt the service or risk other customers' data, is subject to confidentiality, and is at your cost.

Where the Standard Contractual Clauses apply between us, Clause 8.9 governs to the extent of any conflict with this section, and nothing in this section limits your rights under it.

11a. United States state privacy laws

This section applies where you are a business subject to the California Consumer Privacy Act as amended by the California Privacy Rights Act, or to another United States state privacy law of the same kind — those of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and the other states that have enacted comparable laws. It adds to the rest of this DPA rather than replacing it, and where it and another section differ about personal information those laws cover, this section governs. The terms in it are required by those statutes: without them your disclosure of personal information to us would not be compliant, and neither would our receipt of it.

Roles. Under the CCPA you are the business and we are a service provider. Under the other state laws you are the controller and we are the processor. You disclose or make personal information available to us for the limited and specified business purposes set out in section 3, which also describes the categories of personal information, the categories of individuals concerned, and how long the processing lasts.

The restrictions we accept, which those statutes require to be written down. We do not sell your customers' personal information and do not share it, as those statutes define selling and sharing, including for cross-context behavioural advertising; no monetary or other valuable consideration is exchanged for it. We do not retain, use or disclose it for any purpose other than the business purposes specified in this DPA, including not for a commercial purpose of our own, and we do not retain, use or disclose it outside the direct business relationship between you and us. We do not combine it with personal information we receive from or on behalf of another customer, or that we collect from our own dealings with an individual, except as those laws and their regulations permit — to detect and respond to security incidents, to resist malicious, deceptive, fraudulent or illegal activity, to debug and repair errors, and for internal use to build or improve the quality of our services, which never includes building or modifying a profile about an individual. Information that has been deidentified in accordance with those laws is no longer personal information under them; we maintain it in deidentified form, do not attempt to re-identify it, and contractually oblige any recipient to do the same. We do not process it for targeted advertising, and QuoCAD has no feature that does. We do not use it to train machine-learning models.

We will comply with the obligations those laws place on a service provider or processor, and will provide the same level of privacy protection in respect of the personal information you disclose to us as those laws require of you. We certify that we understand the restrictions in the paragraph above and will comply with them.

Your oversight, and what we owe you. You may take reasonable and appropriate steps to satisfy yourself that we use the personal information in a manner consistent with your obligations under those laws; sections 6, 8, 9 and 11 are how we support that in practice, and section 11 sets out what we make available and on what terms. You may take reasonable and appropriate steps to stop and remediate any unauthorised use of it. We will tell you without undue delay if we determine that we can no longer meet an obligation in this section.

Requests from the people concerned. A request to know, access, correct, delete, limit the use of, or opt out belongs to you, for the reason section 8 gives — it is your record and we cannot verify who is asking. Section 8 sets out the help we provide and what it costs. Where you instruct us to delete or correct personal information, we will do so in the systems we operate. Where a subprocessor holds a copy, we will ask it to do the same under the contract required by section 7, and section 10 describes the limits — backups rotate rather than being edited individually.

The processor terms the other state laws require are already in this DPA, so we point at them rather than restate them: processing only on your documented instructions (section 4); a duty of confidentiality on everyone who processes it (section 5); appropriate technical and organizational measures (section 6); engaging a subcontractor only under a written contract imposing obligations no less protective, with our own responsibility for its performance (section 7); assistance with the requests of the people concerned and with your assessments (sections 8 and 9); notifying you of a breach (section 9); deletion or return at your direction at the end of the services (section 10); and making available the information reasonably necessary to demonstrate compliance and allowing a reasonable assessment, which we may satisfy by arranging an assessment and reporting on it (section 11).

Sensitive personal information. Section 3 records that you will not enter it, and QuoCAD has no feature that asks for it. If it reaches us despite that, we do not use or disclose it for any purpose other than performing the services for you, and section 3 governs its removal.

Two honest limits. Whether one of these laws applies to your business is yours to determine, and we do not assess that for you. And accepting these terms for your benefit is not an admission that any of these laws applies to us in our own right.

12. Where data goes, and the safeguards for it

QuoCAD is operated from Canada. Our subprocessors process and store personal data primarily in the United States; the Subprocessors page records the region for each one.

For transfers from the European Economic Area, the European Commission has recognized Canada as providing an adequate level of protection for personal data handled by organizations subject to PIPEDA.

For onward transfers to the United States and elsewhere, we rely on the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and equivalent safeguards in our agreements with each subprocessor.

Where the Standard Contractual Clauses apply directly between us, they are incorporated into this DPA: you are the data exporter and Quocad Inc., of 2150 Winston Park Drive, Unit 203, Oakville, Ontario L6H 5V1, Canada is the data importer, and those are the parties for Annex I(A); Module Two (controller to processor) applies, section 3 of this DPA supplies the Annex I processing description, the Subprocessors page supplies the Annex III list through its Subprocessors group — the independent controllers listed separately on that page are not subprocessors and are not part of Annex III, section 6 supplies the Annex II technical and organizational measures, and the supervisory authority and governing law are those of your establishment. Where the UK Addendum applies, Tables 1 to 3 are completed by the same references and Table 4 is “neither party”.

If you need a countersigned copy of this DPA or of the Clauses for your own records, email us and we will provide one.

13. Term, liability and changes

This DPA takes effect when you accept the Terms of Service and continues for as long as we process your customers' personal data.

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service. Claims under this DPA and claims under the Terms share a single aggregate cap: this DPA does not create a second cap and does not double the first.

We are not liable to you under this DPA for indirect, incidental, special, consequential or punitive damages, or for lost profits, lost revenue, or loss of goodwill.

Your indemnity under section 2a is not subject to that cap and is not subject to the exclusion in the paragraph above: it covers the full amount of the damages, losses, fines, penalties, settlements and costs described in it, however those amounts would be characterised as between us.

Where both of us are found liable to a data subject or to a supervisory authority for the same processing, each bears the share of the liability corresponding to its share of responsibility for the damage, in line with Article 82(5) of the GDPR, and either may recover that share from the other.

Three things no cap in this DPA or in the Terms can reach, stated here rather than left to be argued: liability to a data subject under Article 82 of the GDPR, liability to a supervisory authority, and any liability that applicable data protection law does not allow to be limited. Clause 12 of the Standard Contractual Clauses says the same, and section 12 gives it precedence.

We may update this DPA to reflect a change in the service, in our subprocessors, or in the law. Material changes will be reflected in the effective date above. We will not make a change that materially reduces the protections this DPA gives you during your current subscription term, except where the law requires it.

14. Documents and messages you send

QuoCAD sends quotes, invoices, reminders and receipts to your own customers. Those are your messages: you are the sender, even though they leave our infrastructure and our sending domain, and section 11 of the Terms of Service says the same. We transmit them for you, as your processor, on the instruction you give when you press send.

The allocation follows from that. You choose every recipient and supply every address. You are responsible for having the consent or other permission the law requires for each message — Canada's Anti-Spam Legislation, the United States CAN-SPAM Act, and their equivalents wherever your recipient is — for the address being accurate and lawfully obtained, for the message identifying your business correctly, and for honouring a request to stop. QuoCAD does keep a per-workspace suppression list, and it is enforced: when a provider reports an address as bounced or as a complaint we record it against your workspace, and a later send to that address is blocked before it leaves. That is a deliverability control operated on your behalf, not a consent record — we do not determine whether you have CASL or CAN-SPAM consent for any recipient, we do not review your recipients, and nothing in this DPA obliges us to. The unsubscribe route in the messages you send reaches your business rather than ours, and honouring it remains yours. We do not review your recipients or check a consent, and nothing in this DPA obliges us to. Section 2a covers a claim that a message should not have been sent.

Records that belong to you. For each send, resend, reminder and preview we record, in your workspace and on your behalf, the recipient's name and email address, what kind of message it was, which document it related to, who in your workspace sent it, the provider's message identifier, and whether the send succeeded or failed. We also record that a document was opened, accepted or declined, and any name typed by the person responding. All of that is your workspace content: sections 8 and 10 apply to it, and section 9 of the Terms of Service explains what those records are and are not.

Records that belong to us. Beneath yours sit the operational ones described in section 4a: the delivery, bounce and complaint signals our email provider returns, in which the recipient is identified by a one-way hash rather than by an address; the request logs and rate-limiting records for the page a recipient opens, which section 7c of the Privacy Policy describes; and the delivery metrics we inspect to protect our sending reputation and other customers' deliverability, which section 11 of the Terms of Service allows us to act on.

Share links, and what one actually is. A quote or invoice link is a bearer credential: anyone holding the address can open the document until the link stops working. We store only a one-way hash of it, so the link itself is never in our database and a database read never yields a working one.

A link stops working in three ways, and there is a fourth we do not yet offer. It expires — every link is issued for at least 30 days, and a quote sent on its own carries a link that lasts the quote's own validity period plus a short grace period where that is longer. It is superseded: each document carries one live link, so sending it again replaces the previous link and only the most recent one works. It is overtaken by the document itself — an invoice link stops working once the invoice is voided, revised or refunded, and once the invoice is paid the page can no longer take a payment. And it can be revoked on demand: quotes and invoices both carry a Revoke link control that stops the link resolving immediately, and a Restore that brings the same link back. Revoking an invoice link also stops any combined payment page it served; it does not change the invoice's status, balance or Stripe state. Both actions are written to the audit trail. Until you revoke it, treat a link as live.

Because a link is a bearer credential, who receives it is your decision and your responsibility, including anything that follows from a recipient forwarding one — section 9 of the Terms of Service says the same. Section 3 matters here for the same reason: a document is assembled from the fields you filled in and is then transmitted to whoever you address it to, so what you put in a free-text field is what leaves.

None of this makes us the sender, the controller of your recipient list, or a party to anything between you and your recipient. Nor does it reduce section 9 of this DPA: if personal data is exposed by a failure on our side while we are storing or transmitting one of these documents, that is a personal data breach and we notify you.

15. Notices, contact, and general terms

Notices under this DPA must be in writing to support@quocad.com. Requests for a countersigned copy, subprocessor change notifications, instructions under section 4, assistance requests under section 8, and the deletion-or-return election under section 10 all go to the same address. Notices under this DPA are effective when sent to that address, and section 25 of the Terms of Service (which requires legal notices to go to our registered office) does not apply to them.

Notices from us go to the email address of your workspace owner, to any admin address on your account, and where appropriate to the notification centre inside the product. Keeping those addresses current is your responsibility, and a notice we send to an address on your account is effective when we send it, whether or not you read it. Where a notification under section 9 fails to reach an address on your account, we will use reasonable efforts to reach you another way.

If a provision of this DPA is held unenforceable, it is modified to the smallest extent that makes it enforceable, or if that is not possible, severed — and the rest of it continues in full force.

Sections 2, 2a, 3, 4, 4a, 5, 6, 7, 7a, 8, 9, 10, 11, 11a, 12, 13, 14 and this section survive termination for as long as we hold any of your customers' personal data, along with anything else that by its nature should.

We may assign this DPA, together with the Terms of Service, to a successor in connection with a merger, acquisition, corporate reorganization, or sale of all or substantially all of our assets. You may not assign it without our written consent.

This DPA, the Terms of Service, the Privacy Policy and the Subprocessors page are the whole of what we have agreed about the processing of your customers' personal data, and they replace anything said before them. Where they conflict about that processing, this DPA governs, subject to section 12.

Questions about this DPA, requests for a countersigned copy, and subprocessor change notifications can be sent to support@quocad.com.